EU Export Controls: Our Briefing on Cyber-Surveillance Items Guidelines
Explore the briefing on the EU export guidelines for cyber-surveillance items, focusing on due diligence, risk assessment, and compliance.
Join us for a special report covering the EU’s updated export controls on cyber-surveillance items under Regulation (EU) 2021/821. We’ll delve into the implications of Article 5, outline the due diligence requirements for exporters, and provide insights into identifying and mitigating risks associated with these sensitive technologies. Stay informed on compliance measures and understand the significance of these guidelines for safeguarding human rights and preventing misuse.
Table of Content
I Introduction
II Technical Aspects of Cyber-surveillance Items
III Due Diligence Measures
IV Appendix: Overview of Controlled Cyber-Surveillance Items Under Regulation (EU) 2021/821
You will also be able to download the guidance of the EU on the export of Cyber-Surveillance Items.
I Introduction
What is this all about?
The Union Export Control Framework, established by Regulation (EU) 2021/821, ensures that the EU and its Member States meet their international obligations. These include upholding regional peace, security, and human rights. The EU and its Member States have updated the Union Control List (Annex I) to reflect the latest multilateral decisions on export controls.
Before Article 5 was implemented, Member States monitored the export of certain surveillance items due to the risk of misuse. In some cases, sanctions restricted exports of certain surveillance technologies.
The Regulation aims to prevent cyber-surveillance tools from being used for internal repression or serious human rights violations. It introduces new controls on exports of non-listed cyber-surveillance items. Exporters must notify authorities if, through due diligence, they find that the items they plan to export could be used for internal repression or to commit serious human rights violations.
The guidelines aim to help exporters comply with these new controls by outlining necessary due diligence measures and assessing risks when exporting such items.
Key Legal Provisions
New Export Controls: The Regulation controls the export of non-listed cyber-surveillance items that may be used for internal repression or human rights abuses.
Recital (8): This explains the risks of non-listed cyber-surveillance items, especially when they enable intrusion or deep packet inspection for covert surveillance. Items used for commercial purposes (e.g., billing or network security) are generally not considered high risk.
Recital (9): Highlights the need for harmonised catch-all controls for these items. Member States are encouraged to share information and maintain vigilance.
Article 2, Point 20: This article defines cyber-surveillance items as tools designed for covert surveillance by monitoring or collecting data from information and telecom systems.
Article 5: Introduces the requirement for an export authorisation if authorities inform the exporter that the items may be used for repression or human rights abuses. Exporters must also notify authorities if their due diligence shows a risk.
Article 5(2) requires the Commission and Council to provide exporters with guidelines to support the effective implementation of these controls.
These guidelines are designed to help exporters navigate the new requirements and prevent misuse of cyber-surveillance items.
Key Definitions You Need To Know About
The regulation includes recitals and provisions that clarify important terms for controlling exports of non-listed cyber-surveillance items. These definitions are crucial for exporters to understand to conduct proper due diligence and effectively implement controls. Notably, Article 2, point (20), defines cyber-surveillance items as "dual-use items specially designed to enable the covert surveillance of natural persons by monitoring, extracting, collecting, or analysing data from information and telecommunication systems."
Here are the critical aspects of this definition:
1. ‘Specially Designed’
An item is considered "specially designed" for covert surveillance if its primary purpose is to enable covert monitoring of individuals. However, it doesn’t have to be exclusively for this purpose. Items used for regular commercial activities like billing or network security are not classified as cyber-surveillance items.
2. ‘Covert Surveillance’
Covert surveillance occurs when the person being monitored is unaware and cannot adjust their behaviour or avoid being watched. Even in public spaces, if data is collected secretly or used for purposes unknown to the individual, this can be considered covert surveillance.
3. ‘Natural Persons’
"natural person" refers to a living human being instead of an organisation or legal entity. The regulation does not cover the surveillance of objects or machines, only individuals.
4. ‘Monitoring, Extracting, Collecting, Analysing Data’
These terms describe the technical capabilities of items used for cyber surveillance. For example:
Monitoring: Overseeing or surveillant data transmission.
Extracting: Removing data from systems (e.g., using intrusion software).
Collecting: Gathering data from telecommunication systems.
Analysing: Processing or interpreting data, like using facial recognition technology.
Simple video surveillance or monitoring public traffic does not qualify as cyber-surveillance unless it is combined with other technologies, such as artificial intelligence or big data.
5. ‘Information and Telecommunication Systems’
These systems electronically process or transmit information, such as computer hardware, software, web technologies, or communication systems like radio or optical fibres.
6. ‘Awareness’ and ‘Intended For’
Exporters must notify authorities if they know that cyber-surveillance items will be used for internal repression or human rights violations. "Awareness" means having positive knowledge of misuse, not just the possibility of risk. "Intended for" means that the items are assessed for sensitive end-use based on specific facts, not just theoretical risks.
These definitions are essential to apply the regulation correctly and ensure adequate export controls.
Internal Repression, Human Rights Violations, and International Humanitarian Law
Under Article 15 of the Regulation, Member States must consider all relevant factors, including those from Common Position 2008/944/CFSP, when granting export authorisations.
Internal Repression According to Article 2(2) of the Common Position, internal repression includes actions such as torture, arbitrary executions, and significant human rights violations. The User's Guide suggests considering the track record of the end-user and the recipient country regarding human rights.
Severe Human Rights Violations The export of non-listed cyber-surveillance tools may violate privacy, free expression, and other rights. Misuse could result in repression, including arbitrary detention or torture, especially against vulnerable groups like activists or journalists. Exporters should assess whether the tools could be used to commit serious human rights violations, as defined by international standards.
Serious Violations of International Humanitarian Law International humanitarian law, developed through treaties like the Geneva Conventions, protects civilians and limits warfare methods. Exporters must ensure cyber-surveillance tools are not used to violate these rules in armed conflicts. Serious violations, such as war crimes, should be considered, with guidance available from the User's Guide and the International Committee of the Red Cross.
For both human rights and humanitarian law, violations are considered "serious" if they are widespread or severe, and assessments should be based on reports from recognised international bodies like the UN or the Council of Europe.
II Technical Aspects of Cyber-surveillance Items
Listed Cybersurveillance Items
The Appendix of these guidelines provides details about cyber-surveillance items listed in Annex I of the Regulation. This helps exporters identify non-listed cyber-surveillance items that could be controlled.
Potential Non-Listed Cyber-surveillance Items
It is impossible to provide a complete list of non-listed items under Article 5, but the following products may pose surveillance risks. They should be handled with care under the Regulation.
According to recital (8) of the Regulation, items used for commercial purposes like billing, marketing, quality control, customer satisfaction, or network security typically don't pose misuse risks under human rights or humanitarian law violations.
As such, they are not usually controlled under Article 5. However, exporters should be aware of certain products with information security features (such as cryptography) that fall under Category 5, part 2 of Annex I to the Regulation. Security equipment, like routers and switches that use standard commercial cryptographic functions for administrative purposes, aren't classified as cyber-surveillance items but should still be monitored due to possible misuse.
Facial and Emotion Recognition Technology
Facial and emotion recognition technology can be used for non-surveillance purposes, such as identification or authentication, and doesn’t always fall under the definition of cyber-surveillance items. However, if the technology monitors or analyses stored video images, it could be classified as cyber surveillance. The software's design must also be assessed to determine if it's intended explicitly for covert surveillance.
Location Tracking Devices
Location-tracking devices, used by law enforcement or companies, allow tracking of a device’s physical location over time. These technologies have advanced, including satellite, cell tower, Wi-Fi, and Bluetooth tracking. The widespread use of smartphones and in-vehicle systems may pose surveillance risks. While they have legitimate uses, such as for investigations or commercial purposes (e.g., movement tracking in shopping areas), exporters should be vigilant about potential misuse for surveillance.
Video-Surveillance Systems
Video surveillance systems, including high-resolution cameras used in public spaces, are not classified as cyber-surveillance items under the Regulation because they do not gather or monitor data from information or telecommunication systems.
III Due Diligence Measures
The third section of the document, Due Diligence Measures, outlines the responsibility exporters hold under Regulation (EU) 2021/821 when dealing with dual-use goods and cyber-surveillance items. Key points include:
Importance of Exporters in Trade Control Compliance
Recital 7 highlights exporters' crucial role in supporting trade control compliance through risk assessment measures known as due diligence, which are part of an Internal Compliance Programme (ICP). This program ensures exporters comply with trade regulations and licensing conditions.
Internal Compliance Programme (ICP)
Article 2, point (21), defines the ICP as ongoing policies and procedures that exporters should adopt to manage risks and ensure compliance with the Regulation. An ICP includes, among other elements, due diligence measures that assess risks related to the export of goods, the intended end-users, and the final use of the exported items.
Commission Recommendation (EU) 2019/1318
This recommendation provides a framework to help exporters identify and mitigate risks associated with dual-use goods. It ensures that exporters remain compliant with Union and national regulations, mainly through the transaction-screening measures that are part of due diligence.
Cyber-Surveillance Items
Article 5(2) of the Regulation specifies that exporters of non-listed cyber-surveillance items must conduct due diligence through transaction screening. These steps involve:
Item Classification: Exporters must determine whether their product qualifies as a cyber-surveillance item by examining if it is designed for covert surveillance of individuals by collecting or analysing data from information and communication systems.
Transaction Risk Assessment: This involves evaluating the risk of exporting such items, especially considering their potential misuse. To classify items correctly, exporters must review technical specifications and legal definitions under the Regulation and Annex I.
In practice, exporters must be vigilant about the technical characteristics and intended use of their items, particularly when handling cyber-surveillance technology.
Review of transactions, end-users and consignees
In support of competent authorities, review stakeholders involved in the transaction (including end-users and consignees such as distributors and resellers)
Exporters should review their products' capabilities to ensure foreign end-users won’t misuse them for internal repression or serious violations of human rights and international humanitarian law. This includes assessing whether the item could be used to infringe on rights such as the right to life, freedom from torture, privacy, free speech, and freedom of assembly.
Key points to assess:
Could the product or a part of it be misused in a way that violates human rights?
Could the product be used as part of a system that could result in similar violations?
Red Flags
Exporters should watch for "red flags," warning signs that a transaction may involve an inappropriate end-use or end-user. These red flags include:
The item is marketed for covert surveillance.
Information suggests similar items have been misused for internal repression or human rights violations.
The item has been linked to illegal surveillance of an EU citizen.
The product could be part of a system known for misuse in rights violations.
The item is listed in the Official Journal of the European Union for potential misuse.
Additionally, exporters should support authorities by reviewing the stakeholders involved (e.g., end-users or resellers) and checking how the product will be used based on end-use statements. They should also familiarise themselves with the human rights situation in the destination country to assess the risk of violations.
Key "red flags" for end-users:
The end-user has ties to a government with a record of repression or human rights violations.
The end-user is involved in armed conflict linked to such violations.
The end-user has previously exported surveillance items to countries known for internal repression.
Mitigating measures (Use the due diligence findings to develop plans to prevent and minimise potential adverse impacts).
Based on due diligence findings, exporters should prevent or mitigate any potential negative impacts. This includes:
Updating company policies to prevent future harm.
Strengthening systems to track and flag risks early.
Notifying relevant authorities of high-risk items or transactions.

The image outlines the requirements by Article 5(2) of Regulation (EU) 2021/821, specifically regarding the export of non-listed cyber-surveillance items. This flowchart essentially summarises the process exporters must follow when assessing the export of cyber-surveillance items. It focuses on definitions, technical scope, end-use, and the exporter’s awareness based on due diligence. If risks are identified, they are required to notify the authorities.
Here’s a breakdown of the flowchart:
Export of a non-listed cyber-surveillance item
Definition (Section 1.2)
Technical scope (Section 2)
Intended end-use in connection with:
Internal repression and/or the commission of severe violations of human rights and international humanitarian law
Definitions and guidance (Section 1.3)
Awareness of the exporter based on due diligence findings
Definition (Section 1.2.6)
Guidance (Section 3)
The exporter shall notify the competent authority if all the above requirements are met.
IV Appendix: Overview of Controlled Cyber-Surveillance Items Under Regulation (EU) 2021/821
1. Telecommunication Interception Systems (5A001.f)
Many countries, including EU Member States, have laws protecting communication privacy, but government agencies may conduct covert surveillance under legal frameworks (known as Lawful Interception, or LI). The digital age has made large-scale interception possible, as demonstrated by the Libyan regime's use of such technologies. This led to introducing export controls on telecommunication interception systems in 2012.
Scope of Control: This regulation applies to devices that extract communication content (voice or data), subscriber identifiers, or other metadata sent wirelessly. Examples include:
IMSI Catchers: Devices that intercept mobile phone traffic and track users' movements.
Fake Wi-Fi Hotspots: These can extract IMSI numbers from connected phones.
Deep Packet Inspection Tools: Equipment designed for in-depth analysis of telecommunications data.
Exclusions: Mobile jamming devices are not included, as they do not collect data.
2. Internet Surveillance Systems (5A001.j)
Although much internet communication is encrypted, traffic data (such as IP addresses and data exchange patterns) can still be intercepted to identify relationships between individuals and domain names. Governments may use such systems lawfully for purposes like monitoring criminal activity, but they also risk infringing on human rights and enabling state repression.
Scope of Control: Controls apply to internet monitoring systems that analyze metadata on a national scale, using “hard selectors” to map relationships without the knowledge of targeted individuals. This regulation does not cover social networks or commercial search engines.
3. Intrusion Software (4A005, 4D004, and Related Controls)
Intrusion software enables covert access to electronic devices (e.g., smartphones, laptops) to collect data, eavesdrop, or launch attacks on connected equipment. While some remote access software is legitimate (e.g., IT support), the covert nature of intrusion software raises significant privacy concerns.
Scope of Control: Controls include software and systems specifically designed for intrusion, but they do not apply to the software itself as defined in the regulation. The aim is to mitigate potential harm while allowing cybersecurity researchers to share information to develop protective measures against vulnerabilities.
4. Communication Monitoring Software (5D001.e)
This software is used by law enforcement to analyze data from intercepted communications. It can perform searches using specific criteria and map relationships based on the results. This type of surveillance is covert, and individuals are unaware of their communications being monitored.
Scope of Control: Controls apply to software installed in governmental monitoring facilities but not to lawful interception compliance systems maintained by communication service providers or software designed for commercial purposes.
5. Items for Cryptanalysis (5A004.a)
This control applies to tools that bypass cryptographic protections, allowing unauthorised access to sensitive data, including passwords and cryptographic keys. Cryptanalysis undermines data confidentiality and facilitates covert surveillance.
6. Forensic/Investigative Tools (5A004.b, 5D002.a.3.b, and 5D002.c.3.b)
Forensic tools extract raw data from devices without altering it, aiding legal investigations. They can bypass security controls to access sensitive data, posing privacy and data protection risks.
Scope of Control: Controls apply to tools specifically designed for covert data extraction but exclude general forensic tools not intended for surveillance or those that only extract user data. Equipment used for manufacturing, testing, or commercial purposes is also not covered.
Conclusion
The regulation aims to control various cyber-surveillance technologies to protect privacy and prevent misuse. The application of these controls varies based on the specific technology and its intended use. Each case must be assessed individually to determine compliance with the regulations.


Comments